Index live· 1,284 files · 148 editions
ForensicPost

Search the index

68 results
Try
Results for “HCA Healthcare”Newest first
26-0813
File

19 Million Medical Records Stolen in Polish MyDr Hack

19 million patients, 12,000 clinics, 2.5 terabytes — and a government that will not call it an attack.

UnattributedHealthcareHealthcare
Sev 5TargetMyDrActorUnattributedPoland
26-0714
File

Thirty Million Rows, Claimed. A Limited Number of Systems, Confirmed

Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.

ShinyHuntersVishing → SSO (claimed)HealthcareIdentity
Sev 4TargetAbbott LaboratoriesActorShinyHuntersUSA
26-0731
File

Conduent Breach Affected More Than 62 Million People, Final Count Shows

The final count on the Conduent intrusion landed above 62 million people — third-largest in US healthcare history, at a processor most of them have never heard of.

SafePayRansomwareHealthcareThird party
Sev 5TargetConduent Business SolutionsActorSafePayUSA
26-0721b
File

Patients Learned About an October 2025 Intrusion in July 2026

The remedy is 24 months of monitoring. The scanned passport stays valid for ten years.

UnattributedHealthcareThird party
Sev 4TargetUnlimited SystemsActorUnattributedUSA
26-0716
File

Craneware Discloses Compromise of Hospital Billing and Pricing Software

Revenue-cycle software for thousands of hospitals. Billing data is clinical data wearing an accounting costume.

UnattributedUnder reviewHealthcareHealthcare
Sev 3TargetCranewareActorUnattributedUSA
26-0617
File

A Cardiac Monitor Produces a Continuous Record of You

Ambulatory cardiac data is continuous, and continuous physiology is a behavioural record collected for a clinical reason.

Extortion actor, unnamedThird-party applicationHealthcareMedical devices
Sev 3TargetiRhythmActorExtortion actor, unnamed
26-0613
File

ShinyHunters Claim 8.8TB From Amazon One Medical Legacy Archives

A claimed 8.8 TB from legacy patient archives. Every property that makes a legacy system low priority makes it high value.

ShinyHuntersLegacy archive accessHealthcareHealthcare
Sev 4TargetAmazon One MedicalActorShinyHunters
26-0612
File

DentaQuest Data Published After Extortion Demand Refused

Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.

ShinyHuntersCredential compromiseHealthcareHealthcare
Sev 4TargetDentaQuestActorShinyHunters
26-0503
File

Nine Million Claimed, and the Devices Kept Working

A nine-million-record claim against corporate IT, with device manufacturing reported untouched. The separation is the finding.

ShinyHuntersHealthcareMedical devices
Sev 3TargetMedtronicActorShinyHunters
26-0426
File

Healthcare Ransomware Rose 14% in Early 2026, Concentrated on Suppliers

Hospitals flat, their suppliers up ~35%. Hardening one class of victim redistributes attacks rather than preventing them.

MultipleRansomwareHealthcareAnalysis
Sev 4TargetHealthcare sector suppliersActorMultiple
26-0407
File

Signature Healthcare Diverted Ambulances After Systems Taken Offline

Ambulances diverted, chemotherapy infusions cancelled, a fortnight on paper. The affected people experienced it as a phone call.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetSignature Healthcare (Brockton)ActorUnattributed
26-0324
File

NYC Health + Hospitals Intrusion Touched 1.8 Million People Over Three Months

A three-month intrusion at the largest US public health system took biometric records among the 1.8 million affected. Credit monitoring does not cover a palm print.

UnattributedNetwork intrusionHealthcareHealthcare
Sev 4TargetNYC Health + HospitalsActorUnattributedUSA
26-0304
File

US Healthcare Downtime Costs Around $900,000 per Day

$900,000 a day against demands in the low millions. Printing those two numbers together constructs the attacker’s argument for them.

MultipleRansomwareHealthcareHealthcare
Sev 4TargetUS healthcare providersActorMultipleUSA
26-0218
File

Hospital Caribbean Medical Center Attack Affected About 92,000 People

About 92,000 people at a Puerto Rico hospital. Diversion planning assumes somewhere to divert to.

The GentlemenRansomwareHealthcareHealthcare
Sev 3TargetHospital Caribbean Medical CenterActorThe Gentlemen
26-0210
File

NetRunner Demanded $100 Million From Nippon Medical School Hospital

A reported $100 million demand against a Japanese teaching hospital, and about 131,700 people. Only one of those numbers means anything.

NetRunnerRansomwareHealthcareHealthcare
Sev 4TargetNippon Medical School Musashi KosugiActorNetRunnerJapan
26-0104
File

The Sector Least Able to Absorb This Is the One Being Told to Prepare

The sector with the slowest patch cycle accumulates the most exposure. That needs no prediction about attacker capability.

MultipleUnpatched dependenciesHealthcareAI agents
Sev 4TargetHealthcare technology estateActorMultiple
25-1228b
File

ManageMyHealth Breach Exfiltrated Medical Documents for 120,000 Patients

Documents contain narrative. They describe a person’s condition in terms anybody can read.

UnattributedHealthcareHealthcare
Sev 5TargetManageMyHealthActorUnattributedNew Zealand
25-1222b
File

The Healthcare Year, as This Database Recorded It

One fix is cheap and nobody is doing it: emergency services already record diversion times. Nothing links them to incident dates.

MultipleVariousHealthcareHealthcare
Sev 4TargetHealthcare sectorActorMultiple
25-1220b
File

Four Properties Combine in Healthcare That Combine Nowhere Else

A hospital carries the operational-technology problem of a utility alongside the data-protection problem of a bank.

MultipleRansomwareHealthcareAnalysis
Sev 4TargetHealthcare sectorActorMultiple
25-1218c
File

It Reached the Record Through a Stock Exchange Filing

Two files now where the market regulator surfaced an incident the data regulator would not have.

HealthcareVerification
Sev 2TargetIncident record formationActorUnattributedUnited Kingdom
25-1214b
File

DXS International Incident Hit Clinical Software Used by 2,000 GPs

A patient chooses a practice. The practice chooses the software. The patient has no relationship with the supplier and cannot change it.

UnattributedHealthcareHealthcare
Sev 4TargetDXS InternationalActorUnattributed
25-1215b
File

Five Operations Accounted for Most Attacks on US Healthcare in 2025

Five names, five sectors, one explanation. A list of five describes the head of a very long distribution.

MultipleRansomware-as-a-serviceHealthcareActors
Sev 4TargetUS healthcare providersActorMultipleUSA
25-1211b
File

Medical Organisations Absorbed 22% of Disclosed Ransomware Attacks in 2025

The visibility explanation this desk applies elsewhere is much weaker here. A leak site names whoever the attacker chose to name.

MultipleRansomwareHealthcareHealthcare
Sev 4TargetMedical organisationsActorMultiple
25-1018
File

They Put the Health Records on Telegram

A dark-web listing is read by a professional audience. A Telegram channel is read by neighbours and employers.

UnattributedHealthcareInternational
Sev 4TargetM-TIBAActorUnattributedKenya
25-1010
File

Two Hundred and Seventy-Five Million Patient Records in Two Years

One episode of care generates records in six organisations — six independent breach exposures for the same history.

MultipleVariousHealthcareAnalysis
Sev 4TargetHealthcare sector recordsActorMultiple
25-0802b
File

Health Providers Top the Australian Table Too

Health leading a universal register is a stronger finding than health leading a sector-specific one.

MultipleVariousHealthcareHealthcare
Sev 3TargetAustralian health providersActorMultipleAustralia
25-0801
File

The Biggest Health Breach of the Year Happened at a Company With No Patients

Every year the largest healthcare breach happens at a company patients have never heard of. That is where the data pools.

UnattributedHealthcareThird party
Sev 5TargetHealthcare back-office vendorActorUnattributed
25-0722
File

Interlock and Rhysida Worked Healthcare Without the Older Claimed Limits

The published “we don’t hit hospitals” rules were positioning. An operation whose affiliates pick the victims cannot implement a sector exclusion.

MultipleRansomwareHealthcareActors
Sev 4TargetHealthcare sectorActorMultiple
25-0715
File

One Hospital in Three Says It Affected Patient Care

A third of hospitals say incidents affected care. It measures disruption, not harm — and it still moves the funding argument.

MultipleVariousHealthcareAnalysis
Sev 4TargetUS hospitalsActorMultipleUSA
25-0703
File

Outcomes One Settlement Pays 257,500 People About $6.60 Each

A settlement fund is not an assessment of harm. It is the price of resolving a dispute — here, $6.60 a head.

UnattributedHealthcareLitigation
Sev 3TargetOutcomes OneActorUnattributed
25-0630
File

US Healthcare Reported 343 Breaches Covering 57 Million Records in Six Months

343 mandatory filings in six months. Healthcare tops breach tables partly because it is the only sector compelled to count.

MultipleVariousHealthcareAnalysis
Sev 3TargetUS healthcare sectorActorMultipleUSA
25-0618
File

Aflac Confirms 13.9 Million Affected in the Largest Healthcare Breach of 2025

The reporting duty tracks the sensitivity of the record. The security expectation tracks the sector of the company.

Scattered SpiderSocial engineeringInsuranceInsurance
Sev 5TargetAflacActorScattered Spider
25-0605
File

Episource Ransomware Exposed Data on 5.4 Million People

5.4 million through a subsidiary of the group that had already produced the largest healthcare breach on record.

UnattributedRansomwareHealthcareThird party
Sev 4TargetEpisourceActorUnattributedUSA
25-0520
File

Kettering Health Shut 600 Applications After Attack Affecting 1.7 Million

600 applications withdrawn in a live hospital. Most people guess a few dozen; nobody can say what each one would break.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetKettering HealthActorUnattributedUSA
25-0515
File

Health IT Vendor Ransomware Exposed Data on 442,000 Patients

One vendor incident becomes many provider notifications on different dates. Anyone counting breaches sees several small ones.

UnattributedRansomwareHealthcareThird party
Sev 3TargetHealth IT vendorActorUnattributed
25-0412
File

Interlock Held DaVita for 19 Days and Took Records on 2.7 Million People

Nineteen days inside a dialysis provider, 2.7 million records taken, and treatment never stopped. The continuity is the underreported part.

InterlockRansomwareHealthcareHealthcare
Sev 4TargetDaVitaActorInterlockUSA
25-0410
File

Laboratory Services Cooperative Settles for $6.1 Million Over 1.6 Million Records

Per-capita recovery falls as the class grows. The largest incidents in this database have the weakest claim on the mechanism.

UnattributedHealthcareLitigation
Sev 4TargetLaboratory Services CooperativeActorUnattributed
25-0308
File

Five and a Half Million Patients From One Health System

More affected people than the state has residents. Healthcare is the one sector where “delete what you don’t need” runs into real counter-pressure.

UnattributedHealthcareHealthcare
Sev 4TargetYale New Haven Health SystemActorUnattributed
25-0210
File

Nearly Three Million, Disclosed the Following Year

Not “nearly three million” — 2,947,264. Healthcare produces exact counts because every affected person must be notified.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetPIH HealthActorUnattributed
25-0127b
File

Frederick Health Attack Forced Ambulance Diversion and Delayed Care

EMS already records diversion status and transport time. What does not exist is any mechanism connecting it to a cyber incident.

UnattributedRansomwareHealthcareHealthcare
Sev 5TargetFrederick HealthActorUnattributed
25-0127
File

Frederick Health Ransomware Took Data on More Than 934,000 Patients

934,000 patients, a closed laboratory, and an internal emergency posture that already had a name for this.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetFrederick Health Medical GroupActorUnattributedUSA
24-1219
File

Ascension Disclosed Its Data Figure Seven Months After the Outage

The corpus does not record availability harm less because it matters less. It records it less because nothing compels anyone to measure it.

Black BastaMalicious file downloadHealthcareDisclosure
Sev 5TargetAscensionActorBlack BastaUSA
24-0624
File

Qilin Published Synnovis Data After the NHS Declined to Pay

One paid and the data circulated anyway. One refused and the data was published. The suppression half delivered in neither case.

QilinExtortionHealthcareExtortion
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0620
File

Change Healthcare Affected-Person Count Took Eleven Months to Settle

It did not grow because the intrusion grew. It grew because working out whose records sit in four terabytes takes eleven months.

ALPHVValid credentials, no MFAHealthcareVerification
Sev 5TargetChange HealthcareActorALPHVUSA
24-0610
File

London Hospitals Moved to Universal O Blood After the Synnovis Attack

Universal donor blood exists for trauma, not for encrypted laboratories, and it happened to fit. That is luck rather than planning.

QilinHealthcareFallback
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0604
File

Hospital Investigation Found the Synnovis Attack Contributed to a Patient's Death

The standing objection to everything this database says about availability harm is that nobody can show it reaching a person. Here a trust did.

QilinHealthcareAftermath
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0603
File

Qilin Encryption of Synnovis Cancelled 10,000 Appointments and 1,700 Operations

Those are not records lost. They are appointments that did not happen, to people who were already waiting.

QilinHealthcareAvailability
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0509
File

Ascension Traced Its Intrusion to an Employee Downloading a Malicious File

A hundred and forty hospitals losing their record system is not a proportionate consequence of one download. What sits between is everything it was allowed to reach.

Black BastaMalicious file downloadHealthcareIdentity
Sev 5TargetAscensionActorBlack BastaUSA
24-0508
File

A Hundred and Forty Hospitals, and the Records Went to Paper

The fallback held for a month across 140 hospitals — because enough staff had worked that way before. That is a resource with a retirement date.

Black BastaMalicious file downloadHealthcareAvailability
Sev 5TargetAscensionActorBlack BastaUSA
24-0425
File

Kaiser Permanente Trackers Sent 13.4 Million Members’ Data to Advertisers

A member looking up a condition is not browsing. The page is what reveals the worry.

Tracking technology, by designHealthcareHealthcare
Sev 4TargetKaiser PermanenteActorUnattributedUSA
24-0413
File

Twelve Point Nine Million Records, and No Money to Write the Letters

The practical entitlement reads: you will be told, unless telling you costs more than the organisation has left.

HealthcareVictims
Sev 4TargetMediSecureActorUnattributedAustralia
24-0405
File

They Paid the Operator, and the Affiliate Still Had the Data

A victim negotiating with the brand is negotiating with the party that holds the least. The files sit with the affiliate.

RansomHubRe-extortionHealthcareExtortion
Sev 5TargetChange HealthcareActorRansomHubUSA
24-0301
File

Twenty-two Million Dollars, Paid

A company that pays quietly and says nothing has taken the cheaper path. The sample of known payments is not a sample of payments.

ALPHVExtortionHealthcareExtortion
Sev 5TargetChange HealthcareActorALPHVUSA
24-0221
File

The Change Healthcare Theft and the Ransomware Were a Week Apart

Encryption is the moment the attacker chooses to be seen. It happens after the theft, because the theft is the leverage.

ALPHVValid credentials, no MFAHealthcareDwell
Sev 5TargetChange HealthcareActorALPHVUSA
24-0212
File

Change Healthcare Intruders Used a Citrix Portal With No Second Factor

A written requirement that MFA be enabled everywhere is not a control. It is intent somebody then has to enforce against an estate nobody has fully inventoried.

ALPHVValid credentials, no MFAHealthcareIdentity
Sev 5TargetChange HealthcareActorALPHVUSA
23-1224
File

Integris Health Patients Were Emailed Directly and Offered a $50 Deletion Fee

The pressure did not run through the hospital at all. It ran through the patients.

UnattributedHealthcareHealthcare
Sev 5TargetIntegris HealthActorUnattributedUSA
23-1204
File

23andMe Says 14,000 Accounts Were Stuffed, Reaching 6.9 Million Profiles

14,000 accounts to 6.9 million people. The multiplier was a feature, working as designed.

UnattributedCredential stuffingHealthcareIdentity
Sev 4Target23andMeActorUnattributedUSA
23-1123
File

Ardent Health Took 30 Hospitals Offline After Thanksgiving Ransomware

Diversion is the rare availability harm that produces a number — in minutes, measured by the ambulance service.

UnattributedHealthcareAvailability
Sev 5TargetArdent Health ServicesActorUnattributedUSA
23-1117
File

Welltok Notified 8.5 Million People Over MOVEit, Then the Number Nearly Doubled

An initial figure measures how far a review had got, not how large an incident was.

Cl0pSQL injectionHealthcareHealthcare
Sev 5TargetWelltokActorCl0pUSA
23-0728
File

Maximus Says the MOVEit Flaw Reached Health Data for up to 11 Million People

The campaign is unmeasurable. Its individual victims are not.

Cl0pSQL injectionHealthcareHealthcare
Sev 5TargetMaximusActorCl0pUSA
23-0710
File

HCA Healthcare Reported 11.27 Million Patients Affected by Email Storage Breach

The system with the weakest claim to protection held the widest population. Breadth is what a mail-merge store is for.

UnattributedHealthcareHealthcare
Sev 4TargetHCA HealthcareActorUnattributedUSA
23-0616
File

St Margaret's Health Closed, Citing a 2021 Ransomware Attack Among the Causes

The fatal injury was to cash flow, and it took two years to prove fatal.

UnattributedHealthcareAvailability
Sev 5TargetSt Margaret’s HealthActorUnattributedUSA
23-0512b
File

PharMerica Notified 5.8 Million People After a Two-Day Intrusion in March

Every remedy this database records requires a living person to take an action.

Money MessageHealthcareHealthcare
Sev 4TargetPharMericaActorMoney MessageUSA
22-1218
File

LockBit Apologised to SickKids and Handed Back a Free Decryptor

Pharma is permitted. Dentists are permitted. The line falls where a death could be attributed.

LockBitHealthcareAftermath
Sev 3TargetHospital for Sick ChildrenActorLockBitCanada
22-1024
File

They Refused to Pay, and the Attackers Published the Abortions File

Not a dump. A selection — sorted by which procedure would hurt the patient most.

UnattributedStolen credentialHealthcareAftermath
Sev 5TargetMedibankActorUnattributedAustralia
22-1020
File

Advocate Aurora Told 3 Million Patients Tracking Pixels Sent Data to Meta and Google

No credential stolen, no flaw exploited. Somebody wanted to understand how patients used the portal.

Tracking technology, by designHealthcareHealthcare
Sev 4TargetAdvocate Aurora HealthActorUnattributedUSA
22-1002
File

CommonSpirit Health Ransomware Forced Paper Records Across More Than 100 Facilities

623,700 had data exposed. The people actually harmed were the ones whose procedure moved.

UnattributedHealthcareAvailability
Sev 5TargetCommonSpirit HealthActorUnattributedUSA
22-0328
File

Shields Health Breach Reached 2 Million Patients After an Alert Was Closed as Not Reportable

Something noticed on day eleven. The judgement applied to it is what failed.

UnattributedHealthcareThird party
Sev 4TargetShields Health Care GroupActorUnattributedUSA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging